Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2025-64459SQL Injection in Django

CWE-89SQL Injection12 documents9 sources
Severity
9.1CRITICALNVD
EPSS
0.6%
top 29.36%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 5
Latest updateDec 3

Description

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

CVEListV5djangoproject/django5.25.2.8+2
NVDdjangoproject/django4.24.2.26+2
PyPIdjangoproject/django5.2a15.2.8+2

🔴Vulnerability Details

4
CVEList
Potential SQL injection via _connector keyword argument in QuerySet and Q objects2025-11-05
OSV
CVE-2025-64459: An issue was discovered in 52025-11-05
OSV
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.2025-11-05
GHSA
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.2025-11-05

💥Exploits & PoCs

1
Exploit-DB
Django 5.1.13 - SQL Injection2025-12-03

🔍Detection Rules

3
Suricata
ET WEB_SPECIFIC_APPS Django Privilege Escalation via SQLi (CVE-2025-64459)2025-11-07
Suricata
ET WEB_SPECIFIC_APPS Django Authentication Bypass via SQLi (CVE-2025-64459)2025-11-07
Suricata
ET WEB_SPECIFIC_APPS Django Data Exfiltration via SQLi (CVE-2025-64459)2025-11-07

📋Vendor Advisories

3
Ubuntu
Django vulnerabilities2025-11-05
Red Hat
django: Django SQL injection2025-11-05
Debian
CVE-2025-64459: python-django - An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before ...2025
CVE-2025-64459 — SQL Injection in Djangoproject Django | cvebase